# Why Filebeat returns Unicode character code instead of XML tag symbol under message, it is showing like \\u003c and \\u003e

**URL:** <https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 3, 2019, 8:57am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916 "2019-06-03T08:57:40Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![manjsr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjsr/32/47323_2.png) [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Post date:** [June 3, 2019, 8:57am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/1 "2019-06-03T08:57:40Z")

</div>

I'm new here even for ELK.  
Just trying to use Filebeat to collect XML log and push it to Kafka but Filebeat returns Unicode character code instead of XML tag symbol under message, it is showing like \u003c and \u003e.

I'm using filebeat 6.0.0

**My XML's logs look like this:**  
 ![emp](https://us1.discourse-cdn.com/elastic/original/3X/e/0/e0383e150801a020e1197b1fa1400ebfd007df8c.jpeg)

**My filebeat.yml looks like this:**

 ![filebeat](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6e3a32cf0ab2254849a0ed5f3732c6ef501b0083.jpeg)

**Output getting at Kafka like below**  
{"@timestamp":"2019-06-03T09:08:43.410Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.6.0","topic":"Topic1"},"beat":{"hostname":"LP-5CD812F3VC","version":"6.6.0","name":"LP-5CD812F3VC"},"host":{"name":"LP-5CD812F3VC"},"offset":0,"log":{"file":{"path":"C:\WorkSpace\Filebeat\logs\employees - Copy - Copy (2).xml"},"flags":["multiline"]},"message":"\u003cemployees\u003e\n \u003cemployee id="111"\u003e\n \u003cfirstName\u003eManoj\u003c/firstName\u003e\n \u003clastName\u003eSinha\u003c/lastName\u003e\n \u003clocation\u003eIndia\u003c/location\u003e\n \u003c/employee\u003e\n \u003cemployee id="222"\u003e\n \u003cfirstName\u003eAlex\u003c/firstName\u003e\n \u003clastName\u003eGussin\u003c/lastName\u003e\n \u003clocation\u003eRussia\u003c/location\u003e\n \u003c/employee\u003e\n \u003cemployee id="333"\u003e\n \u003cfirstName\u003eDavid\u003c/firstName\u003e\n \u003clastName\u003eFeezor\u003c/lastName\u003e\n \u003clocation\u003eUSA\u003c/location\u003e\n \u003c/employee\u003e","source":"C:\WorkSpace\Filebeat\logs\employees - Copy - Copy (2).xml","prospector":{"type":"log"},"input":{"type":"log"}}

Can anyone please look into this issue and help me quickly to getting out proper XML tag symbol instead Unicode character code at Filebeat?

Regards, Manoj

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 3, 2019, 10:00am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/2 "2019-06-03T10:00:43Z")

</div>

Do not use screenshots when sharing text. Please paste your configuration here as text and format it using `</>`.

---

<div class="post-metadata">

**Author:** ![manjsr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjsr/32/47323_2.png) [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Post date:** [June 3, 2019, 10:09am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/3 "2019-06-03T10:09:59Z")

</div>

Okay... Thanks. configuration as text.

**Input XML file/logs**

```
<employees>
    <employee id="111">
        <firstName>Manoj</firstName>
        <lastName>Sinha</lastName>
        <location>India</location>
    </employee>
    <employee id="222">
        <firstName>Alex</firstName>
        <lastName>Gussin</lastName>
        <location>Russia</location>
    </employee>
    <employee id="333">
        <firstName>David</firstName>
        <lastName>Feezor</lastName>
        <location>USA</location>
    </employee>
</employees>

```

**My filebeat.yml**

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - C:\WorkSpace\Filebeat\logs\*.xml
    
  input_type: log
  document_type: xml
  encoding: UTF-8
    
  multiline.pattern: '^[[:space:]]'
  multiline.negate: false
  multiline.match: after
  
#----------------------------- Kafka output --------------------------------
output.kafka:
  hosts: ["localhost:9092"]

  topic: "Topic1"

```

**Output getting at Kafka like below**  
`{"@timestamp":"2019-06-03T08:44:16.900Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.6.0","topic":"Topic1"},"offset":0,"log":{"file":{"path":"C:\\WorkSpace\\Filebeat\\logs\\employees - Copy - Copy.xml"},"flags":["multiline"]},"message":"\u003cemployees\u003e\n \u003cemployee id=\"111\"\u003e\n \u003cfirstName\u003eManoj\u003c/firstName\u003e\n \u003clastName\u003eSinha\u003c/lastName\u003e\n \u003clocation\u003eIndia\u003c/location\u003e\n \u003c/employee\u003e\n \u003cemployee id=\"222\"\u003e\n \u003cfirstName\u003eAlex\u003c/firstName\u003e\n \u003clastName\u003eGussin\u003c/lastName\u003e\n \u003clocation\u003eRussia\u003c/location\u003e\n \u003c/employee\u003e\n \u003cemployee id=\"333\"\u003e\n \u003cfirstName\u003eDavid\u003c/firstName\u003e\n \u003clastName\u003eFeezor\u003c/lastName\u003e\n \u003clocation\u003eUSA\u003c/location\u003e\n \u003c/employee\u003e","prospector":{"type":"log"},"input":{"type":"log"},"host":{"name":"LP-5CD812F3VC"},"beat":{"hostname":"LP-5CD812F3VC","version":"6.6.0","name":"LP-5CD812F3VC"},"source":"C:\\WorkSpace\\Filebeat\\logs\\employees - Copy - Copy.xml"}`

Can any one please have a look into this issue and help me quickly to getting out proper XML tag symbol instead Unicode character code at Filebeat?  
@magnusbaeck , @andrewkroh , @pierhugues @ruflin Can you please help me on this quickly?

Regards, Manoj

---

<div class="post-metadata">

**Author:** ![elastikip](https://avatars.discourse-cdn.com/v4/letter/e/3ab097/32.png) [@elastikip](https://discuss.elastic.co/u/elastikip)\
**Post date:** [June 3, 2019, 4:46pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/4 "2019-06-03T16:46:28Z")

</div>

Looks like you need to change the UTF encoding since you are on windows...

encoding: "utf-16le"

---

<div class="post-metadata">

**Author:** ![manjsr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjsr/32/47323_2.png) [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Post date:** [June 4, 2019, 5:24am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/5 "2019-06-04T05:24:11Z")

</div>

I tried every possible combination but filebeat always returns Unicode character code instead of XML tag symbol under message. Even I tried on Linux as well but issue persist there as well.

`"message":" \u003cGroupVersion\u003e0\u003c/GroupVersion\u003e"}`

Any help would be greatly appreciated.. Thanks

---

<div class="post-metadata">

**Author:** ![elastikip](https://avatars.discourse-cdn.com/v4/letter/e/3ab097/32.png) [@elastikip](https://discuss.elastic.co/u/elastikip)\
**Post date:** [June 4, 2019, 12:32pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/6 "2019-06-04T12:32:25Z")

</div>

what version of beats are you using? I found this thread that talks about filebeat behavior in possibly older versions...

> [@Beats encodes angle brackets ("\<" and "\>") as \\u003c and \\u003e in JSON output](https://discuss.elastic.co/t/beats-encodes-angle-brackets-and-as-u003c-and-u003e-in-json-output/60667):
>
> I'm in the process of setting up filebeat to ship out logs on some of my servers. One of my logs has angle brackets in it ("\<" and "\>"). Once filebeat processes it and outputs its JSON representation, those angle brackets have been replaced with \u003c and \u003e, respectively. Sample log: Sep 15 17:49:02 [26263] \<warning\> [rest of log omitted] JSON output: { "@timestamp":"2016-09-16T01:06:24.394Z", "beat":{ "hostname":"[redacted]", "name":"[redacted]" }, "input\_type…

---

<div class="post-metadata">

**Author:** ![manjsr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjsr/32/47323_2.png) [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Post date:** [June 4, 2019, 1:55pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/7 "2019-06-04T13:55:05Z")

</div>

@elastikip, I'm using Filebeat 6.6.0 version. Kindly help me for this issue

```
{"beat":"filebeat","type":"doc","version":"6.6.0","topic":"Topic1"} 

```

Regards, Manoj

---

<div class="post-metadata">

**Author:** ![manjsr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjsr/32/47323_2.png) [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Post date:** [June 6, 2019, 5:58am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/8 "2019-06-06T05:58:43Z")

</div>

Can someone look into this issue and help me to figure out. Any help would be greatly appreciated.

@magnusbaeck , @andrewkroh , @pierhugues @ruflin

Many thanks, Manoj

---

<div class="post-metadata">

**Author:** ![manjsr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjsr/32/47323_2.png) [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Post date:** [June 7, 2019, 7:06am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/9 "2019-06-07T07:06:55Z")

</div>

Hi,  
@tylerjl, @warkolm, @abdon, @Kosho_Owa, @casper

Can someone look into this issue and help me to figure out. Any help would be greatly appreciated.

Regards, Manoj

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [June 7, 2019, 12:08pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/10 "2019-06-07T12:08:12Z")

</div>

Have you tried setting the encoding correctly? The accepted UTF-8 encodings are `utf8` or `utf-.8`.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 9, 2019, 1:55am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/11 "2019-06-09T01:55:50Z")

</div>

Newer versions have an `output.elasticsearch.escape_html` config option that you can set to `false`. I think this would help. In Filebeat 7.0 this defaults to false, but earlier versions had it enabled by default.

[https://www.elastic.co/guide/en/beats/filebeat/6.4/elasticsearch-output.html#\_literal\_escape\_html\_literal](https://www.elastic.co/guide/en/beats/filebeat/6.4/elasticsearch-output.html#_literal_escape_html_literal)

---

<div class="post-metadata">

**Author:** ![manjsr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjsr/32/47323_2.png) [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Post date:** [June 10, 2019, 7:23am UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/12 "2019-06-10T07:23:51Z")

</div>

Thanks @andrewkroh for your suggestion.

I make it **escape\_html: false** like below but still getting same issue. I'm now for filebeat, can you please let me know if i'm missing anything? Just for your referance i'm  
useing Filebeat to collect XML log and push it to Kafka topic.

```
#----------------------------- Kafka output --------------------------------
output.kafka:
  # initial brokers for reading cluster metadata
  hosts: ["localhost:9092"]

  # message topic selection + partitioning
  topic: "Topic1"
  
  codec.json:
    pretty: true
    escape_html: false

```

Output logs at Kafka topic:

```
 message": "\u003cemployees\u003e\n \u003cemployee id=\"111\"\u003e\n \u003cfirstName\u003eLokesh\u003c/firstName\u003e\n \u003clastName\u003eGupta\u003c/lastName\u003e\n \u003clocation\u003eIndia\u003c/location\u003e\n \u003c/employee\u003e\n \u003cemployee id=\"222\"\u003e\n \u003cfirstName\u003eAlex\u003c/firstName\u003e\n \u003clastName\u003eGussin\u003c/lastName\u003e\n \u003clocation\u003eRussia\u003c/location\u003e\n \u003c/employee\u003e\n \u003cemployee id=\"333\"\u003e\n \u003cfirstName\u003eDavid\u003c/firstName\u003e\n \u003clastName\u003eFeezor\u003c/lastName\u003e\n \u003clocation\u003eUSA\u003c/location\u003e\n \u003c/employee\u003e",
  "source": "C:\\WorkSpace\\logs\\employees - Copy.xml",
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 10, 2019, 2:04pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/13 "2019-06-10T14:04:27Z")

</div>

Seems like the `escape_html` setting isn't have any effect in 6.x. I tried 7.1.1 and those escape characters went away.

---

<div class="post-metadata">

**Author:** ![manjsr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manjsr/32/47323_2.png) [@manjsr](https://discuss.elastic.co/u/manjsr)\
**Post date:** [June 11, 2019, 12:37pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/14 "2019-06-11T12:37:03Z")

</div>

Thanks @andrewkroh!!!

Unicode character issue fixed in the latest version of fileBeat. I tested locally with version 7.0.1 (filebeat-7.0.1-windows-x86\_64) with same configuration (v 6.6.0 yml file) and getting expected XML tag at Kafka topic.

But, I have to use filebeat v6.6.0 only and still not able figure out this issue ☹

Regards, Manoj

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 11, 2019, 4:54pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/15 "2019-06-11T16:54:40Z")

</div>

I think opening a bug report on Github is the next step. I think that the `escape_html` is not being honored and some debugging is required.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 6:54pm UTC](https://discuss.elastic.co/t/why-filebeat-returns-unicode-character-code-instead-of-xml-tag-symbol-under-message-it-is-showing-like-u003c-and-u003e/183916/16 "2019-07-09T18:54:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
